paperclipai/paperclip · error

Completion cites a workspace-only file that the user cannot…

Error message

Completion cites a workspace-only file that the user cannot download. Before finishing, use register_deliverable for requested file outputs and cite deliverable:<attachmentId> from the receipt, with /api/attachments/<attachmentId>/content as the download link. For repository changes, cite an accessible PR or registered work product instead. No human completion approval was created.

What it means

When completion prose cites something that looks like a local/workspace file path (file: URI, relative/absolute path, drive letter, or a bare filename-like string) for a requested file output or a registered artifact ref, validateNativeDeliverableEvidence rejects it: workspace-only paths are not downloadable by the end user. Deliverables must be registered via register_deliverable so an /api/attachments/<id>/content link exists.

Solutions

  1. Call register_deliverable for each requested file output and cite deliverable:<attachmentId> from its receipt in the completion text
  2. For repository changes, cite an accessible PR URL or a registered work product instead of a file path
  3. Remove local path references from the completion prose; keep verification commands in the verification field

Example fix

// before
Output saved to ./reports/summary.pdf
// after
Output: deliverable:6a2f4c1e-8b4d-4a2f-9c1e-8b4d4a2f9c1e (download: /api/attachments/6a2f.../content)
Defensive patterns

Strategy: validation

Validate before calling

const LOCAL_PATH_RE = /^(?:file:|\.{0,2}\/|[a-z]:[\\/])|^[^\r\n]+\.[a-z0-9]{1,16}(?::\d+(?::\d+)?)?$/i;
if (LOCAL_PATH_RE.test(ref) && (fileRequested || artifactRefs.has(ref))) {
  throw new Error("Cite deliverable:<attachmentId> instead of a workspace path.");
}

Type guard

const isWorkspacePathRef = (ref) => /^(?:file:|\.{0,2}\/|[a-z]:[\\/])/i.test(ref) || (!/^[a-z][a-z0-9+.-]*:/i.test(ref) && /\.[a-z0-9]{1,16}$/i.test(ref));

Try / catch

try { await feedback(payload); } catch (e) { if (e.message.includes("workspace-only file")) { /* strip local paths, register_deliverable, cite deliverable:<id> */ } else throw e; }

Prevention

When it happens

Trigger: nativeCompletionFeedback / verifyReceipt where refs contain e.g. './report.pdf', '/workspace/out/result.csv', 'file:///tmp/x.png', or 'final-report.pdf' while fileRequested is true or the value is in artifactRefs.

Common situations: Agent summarizes completion with a relative path to the produced file; agent lists output filenames without registering them; Windows-style path cited from a Linux workspace.

Understand the failure class

Background: UnsupportedOperationException and "is not supported" errors: when a library deliberately refuses a call — this error's family across 30 libraries.

Related errors


AI-assisted analysis of paperclipai/paperclip@3f1d897a7c (2026-09-18). Data as JSON: /api/errors/e03de6d229791392. Report an issue: GitHub.

Appendix: source

Thrown at server/src/services/native-runtime/native-deliverable-feedback.ts:134

        throw new Error("Completion cites no registered attachment on this task. Use register_deliverable for the requested file and cite deliverable:<attachmentId> from its receipt. No human completion approval was created.");
      }
      // A prior output (or user input) can be useful context, but does not prove
      // this run published the newly requested output. The receipt survives a
      // controller restart of this run; a replacement can re-register preserved
      // workspace bytes internally rather than asking the user to confirm them.
      if (fileRequested && attachment.originatingRunId !== binding.runId) continue;
      if (fileRequested && !await hasCurrentPublicationReceipt(db, binding.companyId, binding.semanticToolReceipts, attachment)) {
        throw new Error("This attachment has no matching verified publication receipt for this run's requested output. Inspect any preserved file and use register_deliverable to verify its current filename, size, and SHA-256, then cite the new receipt. No human completion approval was created.");
      }
      registeredAttachment = true;
      continue;
    }
    // URLs and typed durable refs are not workspace paths. Verification commands
    // belong in verification; do not scan prose or upload files named by a model.
    const localFile = /^(?:file:|\.{0,2}\/|[a-z]:[\\/])/iu.test(ref)
      || (!/^[a-z][a-z0-9+.-]*:/iu.test(ref) && /^[^\r\n]+\.[a-z0-9]{1,16}(?::\d+(?::\d+)?)?$/iu.test(ref));
    if (localFile && (fileRequested || artifactRefs.has(value))) {
      throw new Error("Completion cites a workspace-only file that the user cannot download. Before finishing, use register_deliverable for requested file outputs and cite deliverable:<attachmentId> from the receipt, with /api/attachments/<attachmentId>/content as the download link. For repository changes, cite an accessible PR or registered work product instead. No human completion approval was created.");
    }
  }
  if (fileRequested && !registeredAttachment) {
    const products = refs.size ? await db.select().from(issueWorkProducts).where(and(
      eq(issueWorkProducts.companyId, binding.companyId), eq(issueWorkProducts.issueId, binding.issueId),
    )) : [];
    const accessibleProduct = products.some(product => {
      if (product.createdByRunId !== binding.runId) return false;
      if (["failed", "cancelled", "archived"].includes(product.status)) return false;
      // A workspace_file resource is only a locator: registration neither checks
      // its current bytes nor keeps them alive after workspace cleanup. Requested
      // files need a published URL or the verified attachment receipt above.
      const accessible = typeof product.url === "string" && /^https?:\/\//iu.test(product.url);
      return accessible && [product.url, `work_product:${product.id}`, `work-product:${product.id}`, `artifact:${product.id}`]
        .some(ref => typeof ref === "string" && refs.has(ref));
    });
    if (!accessibleProduct) throw new Error("The requested file has no accessible delivery evidence. Use register_deliverable and cite deliverable:<attachmentId>, or cite an accessible work product registered by this run for this task. Empty evidence, prior-run output, and a verification result cannot substitute for the requested file. Continue publishing or report a concrete blocker; no human completion approval was created.");
  }

View on GitHub (pinned to 3f1d897a7c)